Apache HTTP Server¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-08-110x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Apache HTTP Server |
CVE-2020-9490 |
DOS |
¸ßΣ |
ÊÇ |
Apache HTTP Server 2.4.20-2.4.43 |
|
CVE-2020-11984 |
BO |
ÖÐΣ |
ÊÇ |
Apache HTTP Server 2.4.32-2.4.43 |
|
|
CVE-2020-11993 |
DOS |
ÖÐΣ |
ÊÇ |
Apache HTTP Server 2.4.20-2.4.43 |
0x01 ·ì϶ÏêÇé
2020Äê8ÔÂ7ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËApache HTTP ServerÖеÄÁ½¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-9490/CVE-2020-11993£©ºÍÒ»¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2020-11984£©£¬¾ßÌåÐÅÏ¢ÈçÏ£º
Apache HTTP Server HTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-9490£©
¸Ã·ì϶ԴÓÚÔÚHTTP/2ÒªÇóÖÐͨ¹ý»ú¹Ø¡¯Cache-Digest¡¯Öµ¿ÉÔì³É·þÎñ±ÀÀ££¬µ¼Ö»ؾø·þÎñ¡£¿ÉһʱÅú¸Ä¡°H2Push off¡±À´»º½â¹¥»÷¡£
Apache HTTP Server HTTP/2»º³åÇøÒç¶Âí½Å£¨CVE-2020-11984£©
mod_proxy_uwsgiÊÇApacheµÄÒ»¸ö·þÎñÄ£¿é£¬ÖØÒªÌṩ¶ÔuwsgiºÍ̸µÄÖ§³Ö¡£¸Ã·ì϶ԴÓÚmod_proxy_uwsgiÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬¿ÉÄܵ¼ÖÂÐÅϢй¶»òÔ¶³Ì´úÂëÖ´ÐС£
Apache HTTP Server HTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-11993£©
¸Ã·ì϶ԴÓÚApache°æ±¾2.4.20ÖÁ2.4.43ΪHTTP2Ä£¿éºÍijЩÁ÷Á¿±ßԵģʽÆôÓøú×Ù/µ÷ÊÔʱ£¬ÔÚÃýÎóµÄÏνÓÉÏÖ´ÐÐÁËÈÕÖ¾¼Í¼Óï¾ä£¬´Ó¶øµ¼Ö²¢·¢Ê¹ÓÃÄÚ´æ³Ø£¬½µµÍ·¨Ê½Óë²Ù×÷ϵͳµÄ»úÄÜ¡£¿ÉһʱÔÚ¡°info¡±ÉÏÅäÖÃmod_http2µÄLogLevelÀ´»º½â¹¥»÷¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼×îа汾£¬ÏÂÔØÁ´½Ó£º
https://httpd.apache.org/download.cgi
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/plugins/nessus/139436
0x04 ²Î¿¼Á´½Ó
https://httpd.apache.org/security/vulnerabilities_24.html
0x05 ¹¦·òÏß
2020-08-07 Apache°ä²¼°²È«²¼¸æ
2020-08-11 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ